CVE-2024-25178: Luajit

Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.

LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler in lj_state.c.

Affected products

  • Luajit Luajit: up to and including 2.1.0

Published 2025-07-07. Last modified 2026-06-17.